Interviews, insight & analysis on digital media & marketing

Chris Burgess of CTI Digital on AI sovereignty: “There are risks to becoming dependent on a frontier model” 

Manchester-based digital transformation agency CTI Digital recently opened public access to Croft, its sovereign AI platform. Croft allows UK organisations to run advanced AI on infrastructure they control – keeping their data, documents and AI activity within the UK rather than on third-party platforms hosted abroad.

The platform pairs private large language models with an organisation’s own knowledge and systems, so employees can securely find and use information, automate repetitive work and build AI-driven processes around their own data, within a single managed environment.

Croft runs on UK infrastructure operated by Nublue, part of the CTI Group, allowing users to run private AI environments,  which can sit within CTI Digital’s managed infrastructure or inside an organisations’ own environment.

New Digital Age spoke with Chris Burgess, Group CEO at CTI Digital, to find out more…

What was the original thinking behind the development of Croft?

I’ve been working in technology for more than 30 years and have been involved in artificial intelligence for around 25 of those. When I joined CTI Digital in May last year, one of the things that really excited me was the opportunity to take the capabilities of a full-stack digital agency and apply them to AI across our customers and the wider digital space.

From the beginning, there was a thought around large language models and AI. But we have these frontier models, mostly based in the US, and if you’re a business using AI to build a process or solve a business problem, there are always questions around your data, intellectual property and resilience.

CTI is also part of a group that includes Nublue, a hosting company. That opened up some interesting possibilities around not just hosting websites, but hosting large language models on GPUs and the infrastructure needed for AI.

So the thinking was always: we’ve got an opportunity here, but if we’re going to do this, we need to own it ourselves.

How does Croft differ from the AI propositions people may have heard of, such as OpenAI and Anthropic?

It’s important to distinguish between a model and the infrastructure around it.

OpenAI has its own model, Anthropic has Claude, and there are many others. Croft itself can use different base models. It could use a Gemini model, an Anthropic model such as Claude, or another model. We can offer that as private AI, where the customer has a choice of model.

The key difference is that frontier models are constantly changing. If you’re building a business process, you don’t necessarily want the latest version of something. You might want a stable, long-term version that you know is going to work consistently.

Croft allows you to take a model, download it and put it on a server or host it privately. That gives you a sustainable, consistent tool that you can use within your business.

It can also be a more specialist model. For example, if you’re a dentist, you might use a model trained around dentistry knowledge. That’s a specific model for your business, rather than a general-purpose frontier model.

Why is AI sovereignty becoming more of an issue for companies?

There are several risks in becoming dependent on a frontier model.

These models can hallucinate or behave unexpectedly, and you’re relying on the guardrails that surround them. We’ve seen situations where changes to a model’s guardrails have resulted in very different outputs. That’s not something you necessarily want to be exposed to as a business.

There’s also the question of whether a model or service can simply become unavailable. We’ve already seen governments restrict the use or distribution of particular AI models because of security concerns. If you’re building a business process around one of those models, there’s a danger of the rug being pulled out from underneath you.

We actually use AI internally at CTI to answer the phone. We were missing around 50 calls a month because we were simply too busy, so now AI answers them. But imagine building that process on a model and then the provider stops offering the service, or the company you’re using goes under. Suddenly you have to scramble to replace something that’s fundamental to your business.

With Croft sitting in your server cabinet or being privately hosted, nobody can take it away from you. Your information is stored privately, and you can use technologies such as retrieval-augmented generation to apply your own data and context.

You can also have agentic workflows operating within that environment. An AI agent could, for example, process emails and learn about your business without exposing your intellectual property or data externally.

That’s the sovereignty argument: it’s UK-hosted, private and under your control.

What has been the market reaction so far to Croft? What sort of client is the offering best suited to?

The reaction has been really good. We launched it publicly last week, having already been using our own version internally, and I’ve spoken to three customers this week. Every one of them wants it.

One example is a customer working in the military who simply can’t use frontier models such as Claude because of where they’re hosted and the associated risks. Having a private model in the back room is much more appropriate for that sort of organisation.

I think there’s a sweet spot in terms of customer size and capability. We’ve worked with organisations that have very sophisticated data scientists who have been building their own large language models for some time. Those organisations are probably too advanced for Croft because they’re already building this capability themselves.

The opportunity is more with organisations that need private AI capability but don’t have the resources or desire to build and manage everything themselves.

How might marketing or media clients make use of Croft?

There are obvious applications around marketing and media content creation, particularly where you want to make sure client information is being handled in the right way.

We’ve all seen examples of AI-generated advertising or content that gets things wrong. There was a well-known example of an AI-generated billboard where the person had five fingers and a thumb. That’s a reminder that you need the right prompting, the right functionality and the right controls around these systems.

For agencies and advertisers, combining an LLM with a managed service from CTI means we can tailor it to the business. You can have the right prompting, the right functionality and the right data environment to drive the business forward without necessarily exposing sensitive client information to a public model.

Beyond AI, what other sorts of support are your clients most commonly asking for right now?

Security is massive at the moment. AI is driving some of that, but cybersecurity, hacking and ransomware have always been important issues. AI makes it easier for people to attack businesses, so security is becoming an even bigger feature.

We’re also seeing a lot of demand around upgrading technology platforms. You’d be surprised how many customers need to upgrade their technology but simply don’t get around to it. No matter how much we knock on the door, sometimes they don’t remember.

It’s a busy time. We’re living through a pretty exciting revolution in digital, and there’s a lot happening beyond AI itself.